Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-506

MITRE ↗

CWE-506

19
CRITICAL
45
HIGH
1
MEDIUM
71 CVEs · Page 2/2
7.5
CVE-2017-16066

opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by n

7.5
CVE-2017-16067

node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16068

ffmepg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

7.5
CVE-2017-16069

nodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16070

nodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by n

7.5
CVE-2017-16071

nodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16072

nodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16073

noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16074

crossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16075

http-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished

7.5
CVE-2017-16076

proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16077

mongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm

7.5
CVE-2017-16078

shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by

7.5
CVE-2017-16079

smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

7.5
CVE-2017-16080

nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by np

7.5
CVE-2017-16081

cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished b

7.5
CVE-2017-16202

The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser

7.5
CVE-2017-16203

The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party se

7.5
CVE-2017-16204

The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server du

7.5
CVE-2017-16205

The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party ser

7.3
CVE-2017-16207

discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.

Frequently Asked Questions

What is CWE-506?

CWE-506 (CWE-506) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-506?

There are 71 CVE records associated with CWE-506 in our database. Of these, 19 are critical severity, 45 are high severity, and 1 are medium severity.

How can I protect against CWE-506 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-506 using AI-powered security agents.

Detect CWE-506 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-506 vulnerabilities across your infrastructure.

Get Started